US11671411B2ActiveUtilityA1

Secure storage and data exchange/sharing system using one time pads

Assignee: INTROSPECTIVE POWER INCPriority: Jan 9, 2017Filed: Nov 10, 2021Granted: Jun 6, 2023
Est. expiryJan 9, 2037(~10.4 yrs left)· nominal 20-yr term from priority
H04L 9/0656H04L 9/321H04L 9/0894H04L 9/12H04L 63/0435H04L 9/0668
52
PatentIndex Score
0
Cited by
6
References
19
Claims

Abstract

A streaming one time Pad cipher using a One Time Pad (OTP) provides secure data storage and retrieval. The data that is encrypted using the one time pad is stored in a repository that is separate from the generation and/or storage for the one time pad.

Claims

exact text as granted — not AI-modified
We claim: 
     
       1. A secure communications method performed by a computing device comprising:
 encrypting a data exchange for communicating to another computing device and decrypting a data exchange provided by the another computing device; 
 communicating with (a) a plurality of one time pad repositories providing a plurality of one time pads for use to encrypt and decrypt said data exchange, and (b) a plurality of data repositories disposed on a plurality of different respective networks, the plurality of data repositories being configured to store different portions of the encrypted data exchange for exchange between the computing device and the another computing device, 
 wherein the plurality of one time pad repositories are not co-located with the plurality of data repositories and the plurality of data repositories are located on different networks, thereby disassociating the one time pads from the stored encrypted data exchange so an attacker cannot determine which one time pads can be used to encrypt or decrypt which portions of the stored encrypted data exchange on which data repository, and 
 communicating via the network interface with at least one authenticator operatively coupled to the plurality of one time pad repositories and the plurality of data repositories, the at least one authenticator authenticating the computing device before permitting the computing device to access the plurality of one time pad repositories and the plurality of data repositories. 
 
     
     
       2. The method of  claim 1  further including generating entropy and using the entropy, generating one time pads that are the same bit sizes as portions of the data exchange to be encrypted. 
     
     
       3. The method of  claim 1  further including:
 decrypting the encrypted data exchange with the another computing device, 
 using the at least one of the plurality of one time pad repositories and access control by the at least one authenticator to provide the another computing device with said one time pads. 
 
     
     
       4. The method of  claim 1  further including associating each of the plurality of one time pad repositories with a one time pad generator that is separate from the computing device, and receiving streaming one time pads from a said one time pad generator after authorization by the at least one authenticator. 
     
     
       5. The method of  claim 1  further including communicating said encrypted data exchange and receiving one time pads from the one time pad repositories over at least one network using network encryption thereby hiding data across the at least one network. 
     
     
       6. The method of  claim 1  further including locating the computing device remotely from the one time pad repositories and the one time pad generator. 
     
     
       7. The method of  claim 1  further including accessing the one time pad repositories and the at least one authenticator in the cloud without relying on any physical or logical connections to the one time pad repositories and the at least one authenticator or any associations therebetween. 
     
     
       8. The method of  claim 1  further including supplying the computing device configured to comprise:
 at least one vector processor, 
 at least one memory, 
 at least one logic controller communicating with the at least one vector processor, the at least one logic controller providing further access to a network controller, 
 an encryption controller, and 
 an entropy source. 
 
     
     
       9. The method of  claim 7  further including operating the computing device remotely from a computer arrangement, and accessing the computer arrangement via a network such as the Internet to store encrypted data for use by a user of the computing device. 
     
     
       10. The method of  claim 1  further including operating the computing device as a client device. 
     
     
       11. The method of  claim 1  further including:
 generating and maintaining an entropy cache separate and remote and otherwise isolated from a transmitter transmitting the encrypted data exchange, 
 communicating using different channels of communication than channels used for transmitting encrypted portions of the data exchange, and 
 securely protecting the transmitter. 
 
     
     
       12. The method of  claim 1  further including:
 providing portions of the data exchange that are at least in part encrypted using a one time Pad to a data repository via a network/cloud, and 
 receiving streamed contents of a one time Pad entropy cache for use in decrypting encrypted portions of a data exchange. 
 
     
     
       13. The method of  claim 1  further including:
 forward caching one time pads or other entropy data to decrease latency, and 
 streaming one time pads continually or discontinually on an on-demand basis for use in encrypting and decrypting. 
 
     
     
       14. The method of  claim 1  further including authenticating to a second client different from a client that stores the encrypted data exchange. 
     
     
       15. The method of  claim 1  further including preventing access by an attacker to a one time pad repository from giving the attacker access to or information about the location of the data repositories storing the encrypted data exchange. 
     
     
       16. The method of  claim 1  further including scattering the plurality of data repositories across the Internet or other network and making the plurality of data repositories different from and in no way associated with the one time pad repositories used to store corresponding one time pads. 
     
     
       17. The method of  claim 1  further including using a private line communication, a virtual private network, or other secure channel to communicate with the plurality of one time pad repositories, thereby avoiding exposing the one time pads to a network based attacker. 
     
     
       18. The method of  claim 1  further including synchronizing at least one of the plurality of one time pad repositories back to a known, consistent state. 
     
     
       19. The method of  claim 1  further including distributing the encrypted data exchange and/or the one time pads across different locations of at least one network.

Join the waitlist — get patent alerts

Track US11671411B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.